Package Health

gottheflag/loom

Loom appears to be a coherent, transparently published new package rather than an abandoned or poorly backed release: the repository matches the package, the README documents usage, the repository contains tests, the package has a license, dependency scope is small, and its workflow uses read-only permissions without detected dangerous patterns. However, this is a very early v0.1.0 release with only one release, no established release cadence, no observed three-month commit activity, and no security policy. Those limitations make its long-term maintenance and maturity unproven, so it is usable with normal caution rather than yet representing a strongly established dependency.

Latest v0.1.0PackagistPackagist

72%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

83

Dependencies
Dependencies
Evaluates the health and security of package dependencies

100

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

89

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

88

Health Score Breakdown

Release historycaution

The package is brand new, with one release and an age of 0 days, so there is no demonstrated release cadence or maintenance track record yet.

Repo commit activitycaution

There were zero commits and zero active maintainers in the measured three-month window. Because the package was released only hours before collection, this is not evidence of abandonment, but it leaves ongoing maintenance unproven.

Security policycaution

No security policy was found, which is a transparency and vulnerability-reporting gap, although the package's very small and newly published scope limits how strongly this weighs.

Version stabilitycaution

The latest version is v0.1.0 and is not a stable major release, which indicates an immature API and a higher chance of breaking changes.

Vulnerabilities

We didn't find any vulnerabilities for this package.

Package versions

Maintainers

Got The Flag

Direct Dependencies

DependencyLast ReleaseScore
symfony/uid
Version ^7.2 || ^8.0

Weekly Downloads

Info

Last Published
13 days ago
Created
13 days ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform